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SUMMARY: (SX{-ON-09-SEPTEMBER~1998;~-AN-ITALIAN- HACKER GROUP (0) 


PARTICIPATED IN SIMULTANEOUS ELECTRONIC ATTACKS (NETSTRIKES) 
ON INTERNET WEBSITES IN MEXICO, GERMANY, AND THE UNITED 
STATES. ITALIAN HACKER GROUP SUPPORTED THE ELECTRONIC ATTACK 
AND PRESENTED THE STATUS OF THE ATTACK AS IT WAS HAPPENING. 
TEXT: _ 

1. }<}--THE-GROUP,- THE ELECTRONIC DISTURBANCE THEATER-(EDT)-;-——~ (I) 
ANNOUNCED AN INTERNET-BASED ELECTRONIC ATTACK (A 
"NETSTRIKE") ON INTERNET WEBSITES IN THE UNITED STATES, 
GERMANY, AND MEXICO ON 05 SEPTEMBER 1998. THE NETSTRIKE 
ANNOUNCEMENT WAS POSTED TO A NUMBER OF DIFFERENT INTERNET 
NEWS GROUPS, INCLUDING AN ITALIAN HACKER INTERNET NEWS 
GROUP. THE ACTION CALLED FOR BY THE EDT WAS FOR "MULTIPLE 
ACTS OF ELECTRONIC CIVIL DISOBEDIENCE" IN SUPPORT OF "THE 
ZAPATISTAS IN CHIAPAS, MEXICO, AND WITH PEOPLE EVERYWHERE 


STRUGGLING AGAINST THE GLOBAL NEOLIBERAL ECONOMY". THE 


NETSTRIKE WAS PLANNED FOR 09 SEPTEMBER AND WAS AIMED AT THE 


FOLLOWING COMPUTER SYSTEMS 


b3 10 USC §130c 
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2. RG THE-EDT- WAS PLANNING~-ON~ PURSUING THE NETSTRIKE IN-- (0) 
CONJUNCTION WITH THE ARS ELECTRONICA FESTIVAL ON INFORMATION 
WARFARE (INFOWAR) HELD IN LINZ, AUSTRIA, FROM 07 - 12 

SEPTEMBER. THE EDT BULLETIN OF 05 SEPTEMBER CALLED FOR 
SYMPATHETIC COMPUTER USERS TO CONNECT THEIR INTERNET WEB 

BROWSERS TO THE EDT'S FLOODNET SOFTWARE LOCATED ON THEIR 

HOMEPAGE AT HTTP://WWW. THING.NET/ 

“RDOM/ZAPSTACTICAL/JAVASCRP.HTM AND 

HTTP: //WWW.NYU.EDU/PROJECTSL____—sJECD.HTML. THE EDT PLANNED ae 
TO USE THEIR FLOODNET SOFTWARE AND THE COMPUTERS OF 

SYMPATHETIC COMPUTER USERS TO EFFECTIVELY BLOCK ACCESS TO 

THESE THREE SITES BY FLOODING THE SITES WITH MORE "HITS" 
(ATTEMPTED INTERNET CONNECTIONS) THAN THE TARGETED COMPUTER 
SYSTEMS COULD EFFECTIVELY NEGOTIATE, CAUSING THE TARGETED 
COMPUTER NETWORK TO EFFECTIVELY DROP OFF-LINE. 

3. Py THE ITALIAN HACKER INTERNET NEWS GROUP POSTINGS 

CONCERNING THE EDT AND THE NETSTRIKE WERE POSTED BY THE 

ITALIAN HACKER WITH THE INTERNET CALL-SIGN "FERRY BYTE". 

FERRY BYTE IS A MEMBER OF THE ITALIAN HACKER GROUP "STRANO 


NETWORK" AND ITS SUBSET "POST AXION MUTANTE". THE STRANO 
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NETWORK IS A PART OF A LARGER CONSORTIUM OF ITALIAN SOCIAL 
ACTIVIST AND HACKER GROUPS KNOWN AS THE "EUROPEAN COUNTER 
NETWORK" (ECN). FERRY BYTE TRANSLATED THE ORIGINAL EDT 
BULLETIN INTO ITALIAN AND POSTED IT TO THE ITALIAN HACKER 
INTERNET NEWS GROUP. IN HIS ITALIAN TRANSLATION OF THE EDT 
BULLETIN, FERRY BYTE ALSO PROVIDED ADDITIONAL SUGGESTIONS 
FOR FACILITATING THE NETSTRIKE. FERRY BYTE RECOMMENDED THAT 
INTERESTED COMPUTER USERS SHOULD PERFORM THE FOLLOWING: 
USERS SHOULD CONTINUALLY "RELOAD" THE DESIGNATED LINK (WHICH 
WOULD CONTINUALLY QUERY THE TARGETED COMPUTER SYSTEM FOR 
ADDITIONAL INFORMATION) ; OPEN AS MANY INTERNET BROWSERS AND 
WINDOWS AS POSSIBLE, QUERYING THE DESIGNATED TARGETED 
COMPUTER SYSTEMS IN EACH OF THE WINDOWS; SET THE MEMORY OF 
THE INTERNET BROWSER'S CACHE TO ZERO; DO NOT START OR ALLOW 
ANY PROXIES FOR THE INTERNET BROWSER; AND DISSEMINATE 


INFORMATION ABOUT THE PLANNED NETSTRIKE TO AS MANY PEOPLE AS 


POSSIBLE. FERRY BYTE ALSO ANNOUNCED THE INTERNET ADDRESS OF 
A SITE WHICH WOULD FACILITATE THE NETSTRIKE BY CONTROLLING 
THE SYMPATHETIC USER'S COMPUTER. THE INTERNET SITE IS 

HTTP: //WWW.THING.NET/*RDOM/ZAPSTACTICAL/ZAPS.HTML. FERRY 


BYTE ALSO PROVIDED THE RELEVANT IP ADDRESSES FOR EACH OF THE 
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TARGETED SITES. FERRY BYTE CONCLUDED BY ADDING THAT THE 


PROGRESS/SUCCESS OF THE NETSTRIKE CAN BE FOLLOWED BY SIMPLY 
TRYING TO "PING" OR PERFORM A TRACE ROUTE (TRACERT) ON THE 
TARGETED SERVERS. (FIELD COMMENT: LONGER "PING" TIMES 


WOULD CORRESPOND TO MORE ACTIVITY ON THE TARGETED COMPUTER 


SYSTEM. THE ULTIMATE GOAL OF THE EDT ORGANIZERS IS THAT THE - 


TARGETED COMPUTER SYSTEM WOULD BE UNREACHABLE. ) 


4. Qe PROGRESS OF THE EDT-ORGANIZED--NETSTRIKE-AGAINST..THE.. 


TARGETED COMPUTER SYSTEMS WAS REPORTED THROUGH VARIOUS 
POSTINGS MADE BY FERRY BYTE ON 09 SEPTEMBER. AT 1216L (ALL 
TIMES HUROPEAN STANDARD TIME) ON 09 SEPTEMBER, FERRY BYTE 
POSTED A MESSAGE TO THE HACKMEETING INTERNET NEWS GROUP 
STATING THAT THE WEBSITE AT 
HTTP://WWW. THING .NET/*RDOM/ZAPSTACTICAL 

/ZAPS.HTML WAS NOT RESPONDING AS OF 1200L AND THAT 
SYMPATHETIC USERS SHOULD TRY TO ACCESS THE TARGETED WEB 
SITES DIRECTLY. AT 1216L, FERRY BYTE ALSO STATED THAT ALI 
THREE OF THE TARGETED WEB SITES ARE APPARENTLY FINDING IT 
MORE DIFFICULT TO OPERATE AND THE WEB SITE OF THE MEXICAN 


PRESIDENT WAS ESPECIALLY SLOW IN RESPONDING. FERRY BYTE 
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CONCLUDED HIS MESSAGE BY STATING THAT NONE OF THE TARGETED 


WEBSITES ARE RESPONDING TO PING COMMANDS DIRECTED AT THEM. 

5. $@)-AP-1243L-ON-09SEPTEMBER; FERRY BYTE PROVIDED AN U) 
UPDATE ON THE STATUS OF THE NETSTRIKE AND STATED THAT 

HTTP: //WWW.THING.NET/*RDOM/ZAPSTACTICAL/ZAPS.HTML WAS ON- 

LINE AGAIN. FERRY BYTE ALSO ADDED AT THIS TIME THAT THE 

TARGETED WEB SITES WERE NOW RESPONDING TO PING COMMANDS, BUT 

THAT THE RESPONSE TIMES WERE MUCH SLOWER THAN NORMAL. AT 

1617 ON 09 SEPTEMBER, FERRY BYTE PROVIDED A THIRD UPDATE ON 

THE STATUS OF THE NETSTRIKE AND STATED THAT THE WHILE THE 

TARGETED SITES WERE STILL ACCESSIBLE WITHOUT TOO MUCH 

DIFFICULTY, THEY WERE RESPONDING MORE SLOWLY. 

6. 4) ee IN-A~RELATED~ POSTING; ANOTHER-ECN--MEMBER [oe nil 
[_____—_—«d|POSTED A MESSAGE TO THE ITALIAN HACKER INTERNET 

NEWS GROUP AT 1850L ON 09 SEPTEMBER STATING THAT A MEMBER OF 

THE EDT,[ —S—~—~——C—CC_] HAD RECEIVED A THREATENING 2 
TELEPHONE CALL. [__ FORWARDED A EDT BULLETIN STATING THAT pas 
[AD RECEIVED A THREATENING PHONE CALL ON 09 

SEPTEMBER AT 0732L IN HIS HOTEL ROOM IN LINZ, AUSTRIA. THE 

BULLETIN REPORTED THAT A UNKNOWN PERSON, PRESUMED TO BE 


MEXICAN, CALLED[ SAT: -HIS HOTEL ROOM, ROOM NUMBER 


PAGE SEVEN DE RUCNFB 0018 | eee ee ® 


610 AT THE STEINBERGER MAXX HOTEL IN LINZ, AUSTRIA. 


ACCORDING TO THE EDT BULLETIN| ——————S—=*dY WAS: THREATENED 

NOT TO GIVE HIS PRESENTATION ABOUT THE NETSTRIKE AT THE ARS ae 
ELECTRONICA INFOWAR FESTIVAL (NFI).[____] NEWSGROUP 

POSTING ALSO PROVIDES ADDITIONAL EDT GUIDANCE FOR 

SYMPATHETIC COMPUTER USERS ON HOW TO CONFIGURE THEIR 

INTERNET BROWSERS IN ORDER TO MAXIMIZE THE POTENTIAL OF THE 

EDT NETFLOOD SOFTWARE: 1) DISABLE JAVA SCRIPT, 2) SET THE 

INTERNET BROSWER PROXIES TO "DIRECT COMMUNICATION TO 

INTERNET", 3) SET INTERNET BROWSER CACHES TO "EVERY TIME", 


AND 4) LEAVE INTERNET BROWSER CONNECTED TO FLOODNET DURING 


THE 24 HOUR NETSTRIKE. 


NETSTRIKE ACTIVITY. ACCORDING TO THE BULLETIN, EDT PLANS TO 
PARTICIPATE IN FUTURE FLOODNET ACTIONS IN CONJUNCTION WITH 
MEXTCAN INDEPENDENCE DAY ON 16 SEPTEMBER, DIA DE LA RAZA ON 
12 OCTOBER, AND CIVIL DISOBEDIENCE AT THE SCHOOL OF THE 
AMERICAS ON 22 NOVEMBER. THE EDT BULLETIN EDT ACTIVITY 
PLANNED AGAINST THE FEDERAL COMMUNICATIONS COMMISSION ON 04 


OCTOBER AND 05 OCTOBER (NFI). 
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8. .(S{- MEMBERS. OF. THE--ECN--HAVE- SUPPORTED A..NUMBER OF uuu 


DIFFERENT SOCIAL CAUSES IN THE PAST. FERRY BYTE CLAIMS THAT 
THE CONCEPT OF A NETSTRIKE WAS CONCEIVED BY THE ITALIAN 
GROUP STRANO NETWORK IN JANUARY 1998 TO SUPPORT THE CHIAPAS 
MOVEMENT IN MBXTICO. FERRY BYTE FURTHER STATED THAT THE 
JANUARY 1998 NETSTRIKE WAS SUCCESSFULLY TARGETED AGAINST 2-3 
MEXICAN INTERNET WEB SITES. IN AN EDT BULLETIN, EDT STATED 
THAT THEY HAVE BEEN USING ITS FLOODNET SOFTWARE SINCE APRIL 
1998 TO "ENGAGE IN VIRTUAL SIT-INS ON THE WEB SITES OF THE 


MEXICAN GOVERNMENT AND THE CLINTON WHITE HOUSE". 


9. (<)-ON 26°SEPTEMBER, EDT MemBER[—_—SS POSTED a 
MESSAGE TO AN INTERNET NEWS GROUP THAT HE HAD BEEN FORCED TO 
REMOVE THE EDT WEBSITE FROM THE NEW YORK UNIVERSITY'S (NYU) 
WEB SERVER.[_————«| STATED THAT THE MOVE WAS REQUIRED 
FOLLOWING AN EMAIL FROM THE DEFENSE INFORMATION SYSTEMS 
AGENCY (DISA) AUTOMATED SYSTEM SECURITY INCIDENT SUPPORT 
TEAM (ASSIST) TO THE NYU COMPUTER SECURITY MANAGER. 
[________]ANNOUNCED THAT THE NEW WEB SITE ADDRESS FOR THE EDT 
AND ITS FLOODNET PROJECT IS LOCATED AT 

HTTP: //WWW.THING.NET/*RDOM/ECD/ECD.HTML. 


COMMENTS : (FIELD COMMENTS) 1. (C) IT IS ANTICIPATED THAT 


tem 


b7Cc 
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a 


THERE WILL BE AN INCREASE IN NETSTRIKES AGAINST DOD SITES AS 


THESE SOCIAL ACTIVISTS/HACKER GROUPS SUPPORT MORE CAUSES 


WHICH THEY PERCEIVE THE DOD TO BE INIMICAL TO. 


WARNING: (U) REPORT IS CLASSIFIED CO N-F-i-p-E-3-T TAL. 
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